GitLab의 주요 GraphQL 취약점으로 비인증 공격자가 공개 프로젝트를 삭제할 수 있음.
GitLab은 비인증 공격자가 공개 프로젝트 및 사용자 데이터를 원격으로 수정하거나 삭제할 수 있는 주요 취약점을 해결하는 보안 업데이트를 발표했습니다. 이 결함은 CVE-2026-19478로 추적되며 GitLab에 의해 Critical로 분류되었고 CVSS 점수는 9.4입니다. 해당 취약점은 Community Edition(CE)과 Enterprise Edition(EE) 소프트웨어 모두에 영향을 미칩니다.
A critical GitLab GraphQL flaw could let unauthenticated attackers delete public projects.
GitLab has released security updates to address a critical vulnerability that could allow unauthenticated attackers to remotely modify or delete public projects and user data. This flaw is tracked as CVE-2026-19478 and has been rated Critical by GitLab with a CVSS score of 9.4. It affects both the Community Edition (CE) and Enterprise Edition (EE) software.